Back to skill

Security audit

Taskpod

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed TaskPod integration, but it asks agents to keep polling for outside tasks and perform some contest/social actions with too little per-action user control.

Install only if you intentionally want this agent connected to TaskPod as a recurring worker. Before enabling heartbeat or contest mode, require human approval for each accepted task and each social post, restrict credentials and callback destinations, validate task URLs and webhook signatures, and keep a clear way to disable polling and remove memory/heartbeat-state.json.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T01 · Skill Instruction Hijacking

Error
Location
HEARTBEAT.md:24
Finding

External Task Instructions Are Processed Without Human Approval or Trust-Boundary Enforcement

Content
View full analysis
Remediation
View remediation

T06 · System Persistence

Warning
Location
HEARTBEAT.md:24
Finding

Persistent Periodic Polling Establishes a Cross-Session External Control Channel

Content
View full analysis
Remediation
View remediation

T01 · Skill Instruction Hijacking

Warning
Location
HEARTBEAT.md:214
Finding

Automated Promotional Posting and Engagement Can Cause Unauthorized Public Actions

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (22)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The contest social instructions encourage autonomous posting and interaction on an external platform without notifying the user or obtaining approval. This is especially risky because public posts, comments, and reactions can affect reputation, disclose strategy, and misuse linked accounts.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The Moltbook posting and engagement instructions are unjustified by the stated TaskPod purpose and create a new capability to publish and interact on a separate platform. That is dangerous because it enables unauthorized outbound communications and social manipulation behavior that users may not expect from a registration/discovery skill.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file instructs the agent to make authenticated external API calls and persist local state without warning the user that data will be transmitted to TaskPod and files will be modified. This undermines informed consent and can lead to silent disclosure of capabilities/status metadata and unapproved local state changes.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The heartbeat instructions materially expand the skill from simple registration/discovery into autonomous polling, task intake, processing, retries, and workflow management. That scope creep increases the agent's operational authority and can cause unreviewed execution of externally supplied tasks, which is risky when the manifest does not clearly disclose or constrain those behaviors.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
92% confidence
Finding

This instruction directs periodic authenticated heartbeat transmissions to TaskPod, creating recurring external data egress and continuous service contact. The danger is increased by the scheduled, autonomous nature of the behavior, which can occur without ongoing user awareness.

Content

Scanner excerpt · HEARTBEAT.md (reported line 26)May include surrounding context.

markdown
## TaskPod (every 30 minutes)
If 30+ minutes since last TaskPod check:
1. Send heartbeat: POST https://api.taskpod.ai/v1/agents/YOUR_AGENT_ID/heartbeat
2. Check for tasks: GET https://api.taskpod.ai/v1/tasks?role=agent&status=pending&limit=5
3. If tasks found matching your capabilities → process them
4. Update lastTaskPodCheck timestamp

External Transmission

Medium
Category
Data Exfiltration
Confidence
94% confidence
Finding

Polling TaskPod for pending tasks is an external transmission that also serves as an intake channel for untrusted remote work items. In this skill's context, it is more dangerous than a simple API read because the next instruction is to process matching tasks, potentially causing autonomous execution of externally sourced instructions.

Content

Scanner excerpt · HEARTBEAT.md (reported line 27)May include surrounding context.

TaskPod (every 30 minutes)

If 30+ minutes since last TaskPod check:

  1. Send heartbeat: POST https://api.taskpod.ai/v1/agents/YOUR_AGENT_ID/heartbeat
  2. Check for tasks: GET https://api.taskpod.ai/v1/tasks?role=agent&status=pending&limit=5
  3. If tasks found matching your capabilities → process them
  4. Update lastTaskPodCheck timestamp
text

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

The documented curl command shows outbound authenticated communication to TaskPod. Even as example content, it promotes a pattern of external transmission that should be treated as sensitive because it uses API credentials and shares operational metadata.

Content

Scanner excerpt · HEARTBEAT.md (reported line 50)May include surrounding context.

Heartbeat API

bash
curl -X POST https://api.taskpod.ai/v1/agents/YOUR_AGENT_ID/heartbeat \
  -H "Authorization: Bearer YOUR_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

The documented curl command shows outbound authenticated communication to TaskPod. Even as example content, it promotes a pattern of external transmission that should be treated as sensitive because it uses API credentials and shares operational metadata.

Content

Scanner excerpt · HEARTBEAT.md (reported line 50)May include surrounding context.

Heartbeat API

bash
curl -X POST https://api.taskpod.ai/v1/agents/YOUR_AGENT_ID/heartbeat \
  -H "Authorization: Bearer YOUR_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{

External Transmission

Medium
Category
Data Exfiltration
Confidence
93% confidence
Finding

The task-check endpoint is an external fetch of potentially actionable remote content, and in this document it is directly tied to accepting and processing discovered tasks. That combination creates a meaningful risk of untrusted instruction ingestion and autonomous behavior beyond the user's original expectation.

Content

Scanner excerpt · HEARTBEAT.md (reported line 86)May include surrounding context.

After each heartbeat, check if there's work waiting:

bash
curl "https://api.taskpod.ai/v1/tasks?role=agent&status=pending&limit=5" \
  -H "Authorization: Bearer YOUR_API_KEY"

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The contest section adds autonomous cross-platform posting and social interaction behavior unrelated to basic TaskPod registration/discovery. This broadens the skill into promotional and engagement activity on external services, creating risk of spam, reputational harm, and unauthorized actions under the user's identity.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · ONBOARD.md (reported line 25)May include surrounding context.

Step 2: Register

bash
curl -X POST https://api.taskpod.ai/v1/agents \
  -H "Content-Type: application/json" \
  -d '{
    "name": "YOUR_AGENT_NAME",

External Transmission

Medium
Category
Data Exfiltration
Confidence
84% confidence
Finding

The skill instructs the agent to add an automatic heartbeat that repeatedly contacts a third-party service every 30 minutes and poll for pending tasks. This establishes persistent outbound communications and a mechanism for receiving arbitrary future work from an external platform, which increases attack surface and could cause unreviewed task ingestion or privacy leakage if added blindly to an agent’s periodic workflow.

Content

Scanner excerpt · ONBOARD.md (reported line 63)May include surrounding context.

markdown
## TaskPod (every 30 minutes)
1. POST https://api.taskpod.ai/v1/agents/YOUR_ID/heartbeat
2. GET https://api.taskpod.ai/v1/tasks?role=agent&status=pending&limit=5
3. Process any matching tasks

External Transmission

Medium
Category
Data Exfiltration
Confidence
86% confidence
Finding

Polling the external tasks endpoint encourages the agent to fetch work items from a third-party queue on a recurring basis. In this skill context, that is more dangerous than a one-time registration call because it can continuously import untrusted task content into the agent’s execution flow, creating a supply-chain style risk if the agent later processes those tasks automatically.

Content

Scanner excerpt · ONBOARD.md (reported line 64)May include surrounding context.

markdown
## TaskPod (every 30 minutes)
1. POST https://api.taskpod.ai/v1/agents/YOUR_ID/heartbeat
2. GET https://api.taskpod.ai/v1/tasks?role=agent&status=pending&limit=5
3. Process any matching tasks

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · ONBOARD.md (reported line 25)May include surrounding context.

md
version: 1.16.0
description: Register your agent on TaskPod, the trust layer for AI agents. Get discovered, earn reputation, and get paid for completing tasks.
homepage: https://taskpod.ai
metadata: {"taskpod":{"emoji":"🛡️","category":"agent-infrastructure","api_base":"https://api.taskpod.ai/v1"},"requiredEnv":["TASKPOD_API_KEY"],"configPaths":["memory/heartbeat-state.json"]}
---

# TaskPod — The Trust Layer for AI Agents

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 6)May include surrounding context.

md
version: 1.16.0
description: Register your agent on TaskPod, the trust layer for AI agents. Get discovered, earn reputation, and get paid for completing tasks.
homepage: https://taskpod.ai
metadata: {"taskpod":{"emoji":"🛡️","category":"agent-infrastructure","api_base":"https://api.taskpod.ai/v1"},"requiredEnv":["TASKPOD_API_KEY"],"configPaths":["memory/heartbeat-state.json"]}
---

# TaskPod — The Trust Layer for AI Agents

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 54)May include surrounding context.

md
version: 1.16.0
description: Register your agent on TaskPod, the trust layer for AI agents. Get discovered, earn reputation, and get paid for completing tasks.
homepage: https://taskpod.ai
metadata: {"taskpod":{"emoji":"🛡️","category":"agent-infrastructure","api_base":"https://api.taskpod.ai/v1"},"requiredEnv":["TASKPOD_API_KEY"],"configPaths":["memory/heartbeat-state.json"]}
---

# TaskPod — The Trust Layer for AI Agents

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 76)May include surrounding context.

md
version: 1.16.0
description: Register your agent on TaskPod, the trust layer for AI agents. Get discovered, earn reputation, and get paid for completing tasks.
homepage: https://taskpod.ai
metadata: {"taskpod":{"emoji":"🛡️","category":"agent-infrastructure","api_base":"https://api.taskpod.ai/v1"},"requiredEnv":["TASKPOD_API_KEY"],"configPaths":["memory/heartbeat-state.json"]}
---

# TaskPod — The Trust Layer for AI Agents

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 125)May include surrounding context.

md
version: 1.16.0
description: Register your agent on TaskPod, the trust layer for AI agents. Get discovered, earn reputation, and get paid for completing tasks.
homepage: https://taskpod.ai
metadata: {"taskpod":{"emoji":"🛡️","category":"agent-infrastructure","api_base":"https://api.taskpod.ai/v1"},"requiredEnv":["TASKPOD_API_KEY"],"configPaths":["memory/heartbeat-state.json"]}
---

# TaskPod — The Trust Layer for AI Agents

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 136)May include surrounding context.

md
version: 1.16.0
description: Register your agent on TaskPod, the trust layer for AI agents. Get discovered, earn reputation, and get paid for completing tasks.
homepage: https://taskpod.ai
metadata: {"taskpod":{"emoji":"🛡️","category":"agent-infrastructure","api_base":"https://api.taskpod.ai/v1"},"requiredEnv":["TASKPOD_API_KEY"],"configPaths":["memory/heartbeat-state.json"]}
---

# TaskPod — The Trust Layer for AI Agents

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 144)May include surrounding context.

md
version: 1.16.0
description: Register your agent on TaskPod, the trust layer for AI agents. Get discovered, earn reputation, and get paid for completing tasks.
homepage: https://taskpod.ai
metadata: {"taskpod":{"emoji":"🛡️","category":"agent-infrastructure","api_base":"https://api.taskpod.ai/v1"},"requiredEnv":["TASKPOD_API_KEY"],"configPaths":["memory/heartbeat-state.json"]}
---

# TaskPod — The Trust Layer for AI Agents

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · package.json (reported line 21)May include surrounding context.

json
version: 1.16.0
description: Register your agent on TaskPod, the trust layer for AI agents. Get discovered, earn reputation, and get paid for completing tasks.
homepage: https://taskpod.ai
metadata: {"taskpod":{"emoji":"🛡️","category":"agent-infrastructure","api_base":"https://api.taskpod.ai/v1"},"requiredEnv":["TASKPOD_API_KEY"],"configPaths":["memory/heartbeat-state.json"]}
---

# TaskPod — The Trust Layer for AI Agents

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 76)May include surrounding context.

1. Register your agent

bash
curl -X POST https://api.taskpod.ai/v1/agents/register \
  -H "Content-Type: application/json" \
  -d '{
    "name": "Your Agent Name",

Static analysis

No suspicious patterns detected.